IPSEC-SPD-MIB

This MIB module defines configuration objects for managing
IPsec Security Policies.  In general, this MIB can be
implemented anywhere IPsec security services exist (e.g.,
bump-in-the-wire, host, gateway, firewall, router, etc.).
        
Copyright (C) The IETF Trust (2007).  This version of
this MIB module is part of RFC 4807; see the RFC itself for
full legal notices.
    

Imported Objects

diffServMultiFieldClfrNextFree, IfDirection, diffServMIBMultiFieldClfrGroupDIFFSERV-MIB
InterfaceIndexIF-MIB
InetAddress, InetAddressTypeINET-ADDRESS-MIB
SnmpAdminStringSNMP-FRAMEWORK-MIB
NOTIFICATION-GROUP, OBJECT-GROUP, MODULE-COMPLIANCESNMPv2-CONF
OBJECT-TYPE, mib-2, Unsigned32, Integer32, NOTIFICATION-TYPE, MODULE-IDENTITYSNMPv2-SMI
VariablePointer, StorageType, TimeStamp, TruthValue, RowStatus, TEXTUAL-CONVENTIONSNMPv2-TC

Type Definitions (4)

Name Base Type Values/Constraints
SpdAdminStatusEnumerationenabled(1), disabled(2)
SpdBooleanOperatorEnumerationor(1), and(2)
SpdIPPacketLoggingInteger32range: -1..65535
SpdTimePeriodOctetStringrange: 0..31

Objects

spdMIB .1.3.6.1.2.1.153
spdConfigObjects .1.3.6.1.2.1.153.1
spdLocalConfigObjects .1.3.6.1.2.1.153.1.1
spdIngressPolicyGroupName .1.3.6.1.2.1.153.1.1.1
spdEgressPolicyGroupName .1.3.6.1.2.1.153.1.1.2
spdIpsoHeaderFilterTable .1.3.6.1.2.1.153.1.10
spdIpsoHeaderFilterEntry .1.3.6.1.2.1.153.1.10.1
spdIpsoHeadFiltName .1.3.6.1.2.1.153.1.10.1.1
spdIpsoHeadFiltType .1.3.6.1.2.1.153.1.10.1.2
spdIpsoHeadFiltClassification .1.3.6.1.2.1.153.1.10.1.3
spdIpsoHeadFiltProtectionAuth .1.3.6.1.2.1.153.1.10.1.4
spdIpsoHeadFiltLastChanged
.1.3.6.1.2.1.153.1.10.1.5
spdIpsoHeadFiltStorageType
.1.3.6.1.2.1.153.1.10.1.6
spdIpsoHeadFiltRowStatus
.1.3.6.1.2.1.153.1.10.1.7
spdCompoundActionTable .1.3.6.1.2.1.153.1.11
spdCompoundActionEntry .1.3.6.1.2.1.153.1.11.1
spdCompActName .1.3.6.1.2.1.153.1.11.1.1
spdCompActExecutionStrategy .1.3.6.1.2.1.153.1.11.1.2
spdCompActLastChanged
.1.3.6.1.2.1.153.1.11.1.3
spdCompActStorageType
.1.3.6.1.2.1.153.1.11.1.4
spdCompActRowStatus
.1.3.6.1.2.1.153.1.11.1.5
spdSubactionsTable .1.3.6.1.2.1.153.1.12
spdSubactionsEntry .1.3.6.1.2.1.153.1.12.1
spdSubActPriority .1.3.6.1.2.1.153.1.12.1.1
spdSubActSubActionName
.1.3.6.1.2.1.153.1.12.1.2
spdSubActLastChanged
.1.3.6.1.2.1.153.1.12.1.3
spdSubActStorageType
.1.3.6.1.2.1.153.1.12.1.4
spdSubActRowStatus
.1.3.6.1.2.1.153.1.12.1.5
spdStaticActions .1.3.6.1.2.1.153.1.13
spdDropAction .1.3.6.1.2.1.153.1.13.1
spdDropActionLog .1.3.6.1.2.1.153.1.13.2
spdAcceptAction .1.3.6.1.2.1.153.1.13.3
spdAcceptActionLog .1.3.6.1.2.1.153.1.13.4
spdEndpointToGroupTable .1.3.6.1.2.1.153.1.2
spdEndpointToGroupEntry .1.3.6.1.2.1.153.1.2.1
spdEndGroupDirection
.1.3.6.1.2.1.153.1.2.1.1
spdEndGroupInterface
.1.3.6.1.2.1.153.1.2.1.2
spdEndGroupName .1.3.6.1.2.1.153.1.2.1.3
spdEndGroupLastChanged
.1.3.6.1.2.1.153.1.2.1.4
spdEndGroupStorageType
.1.3.6.1.2.1.153.1.2.1.5
spdEndGroupRowStatus
.1.3.6.1.2.1.153.1.2.1.6
spdGroupContentsTable .1.3.6.1.2.1.153.1.3
spdGroupContentsEntry .1.3.6.1.2.1.153.1.3.1
spdGroupContName .1.3.6.1.2.1.153.1.3.1.1
spdGroupContPriority .1.3.6.1.2.1.153.1.3.1.2
spdGroupContFilter
.1.3.6.1.2.1.153.1.3.1.3
spdGroupContComponentType .1.3.6.1.2.1.153.1.3.1.4
spdGroupContComponentName .1.3.6.1.2.1.153.1.3.1.5
spdGroupContLastChanged
.1.3.6.1.2.1.153.1.3.1.6
spdGroupContStorageType
.1.3.6.1.2.1.153.1.3.1.7
spdGroupContRowStatus
.1.3.6.1.2.1.153.1.3.1.8
spdRuleDefinitionTable .1.3.6.1.2.1.153.1.4
spdRuleDefinitionEntry .1.3.6.1.2.1.153.1.4.1
spdRuleDefName .1.3.6.1.2.1.153.1.4.1.1
spdRuleDefDescription
.1.3.6.1.2.1.153.1.4.1.2
spdRuleDefFilter
.1.3.6.1.2.1.153.1.4.1.3
spdRuleDefFilterNegated
.1.3.6.1.2.1.153.1.4.1.4
spdRuleDefAction
.1.3.6.1.2.1.153.1.4.1.5
spdRuleDefAdminStatus .1.3.6.1.2.1.153.1.4.1.6
spdRuleDefLastChanged
.1.3.6.1.2.1.153.1.4.1.7
spdRuleDefStorageType
.1.3.6.1.2.1.153.1.4.1.8
spdRuleDefRowStatus
.1.3.6.1.2.1.153.1.4.1.9
spdCompoundFilterTable .1.3.6.1.2.1.153.1.5
spdCompoundFilterEntry .1.3.6.1.2.1.153.1.5.1
spdCompFiltName .1.3.6.1.2.1.153.1.5.1.1
spdCompFiltDescription
.1.3.6.1.2.1.153.1.5.1.2
spdCompFiltLogicType .1.3.6.1.2.1.153.1.5.1.3
spdCompFiltLastChanged
.1.3.6.1.2.1.153.1.5.1.4
spdCompFiltStorageType
.1.3.6.1.2.1.153.1.5.1.5
spdCompFiltRowStatus
.1.3.6.1.2.1.153.1.5.1.6
spdSubfiltersTable .1.3.6.1.2.1.153.1.6
spdSubfiltersEntry .1.3.6.1.2.1.153.1.6.1
spdSubFiltPriority .1.3.6.1.2.1.153.1.6.1.1
spdSubFiltSubfilter
.1.3.6.1.2.1.153.1.6.1.2
spdSubFiltSubfilterIsNegated
.1.3.6.1.2.1.153.1.6.1.3
spdSubFiltLastChanged
.1.3.6.1.2.1.153.1.6.1.4
spdSubFiltStorageType
.1.3.6.1.2.1.153.1.6.1.5
spdSubFiltRowStatus
.1.3.6.1.2.1.153.1.6.1.6
spdStaticFilters .1.3.6.1.2.1.153.1.7
spdTrueFilter .1.3.6.1.2.1.153.1.7.1
spdTrueFilterInstance .1.3.6.1.2.1.153.1.7.1.0
spdIpOffsetFilterTable .1.3.6.1.2.1.153.1.8
spdIpOffsetFilterEntry .1.3.6.1.2.1.153.1.8.1
spdIpOffFiltName .1.3.6.1.2.1.153.1.8.1.1
spdIpOffFiltOffset .1.3.6.1.2.1.153.1.8.1.2
spdIpOffFiltType .1.3.6.1.2.1.153.1.8.1.3
spdIpOffFiltValue .1.3.6.1.2.1.153.1.8.1.4
spdIpOffFiltLastChanged
.1.3.6.1.2.1.153.1.8.1.5
spdIpOffFiltStorageType
.1.3.6.1.2.1.153.1.8.1.6
spdIpOffFiltRowStatus
.1.3.6.1.2.1.153.1.8.1.7
spdTimeFilterTable .1.3.6.1.2.1.153.1.9
spdTimeFilterEntry .1.3.6.1.2.1.153.1.9.1
spdTimeFiltName .1.3.6.1.2.1.153.1.9.1.1
spdTimeFiltPeriod .1.3.6.1.2.1.153.1.9.1.2
spdTimeFiltMonthOfYearMask .1.3.6.1.2.1.153.1.9.1.3
spdTimeFiltDayOfMonthMask .1.3.6.1.2.1.153.1.9.1.4
spdTimeFiltDayOfWeekMask .1.3.6.1.2.1.153.1.9.1.5
spdTimeFiltTimeOfDayMask .1.3.6.1.2.1.153.1.9.1.6
spdTimeFiltLastChanged
.1.3.6.1.2.1.153.1.9.1.7
spdTimeFiltStorageType
.1.3.6.1.2.1.153.1.9.1.8
spdTimeFiltRowStatus
.1.3.6.1.2.1.153.1.9.1.9
spdNotificationObjects .1.3.6.1.2.1.153.2
spdNotifications .1.3.6.1.2.1.153.2.0
spdNotificationVariables .1.3.6.1.2.1.153.2.1
spdActionExecuted
.1.3.6.1.2.1.153.2.1.1
spdIPEndpointAddType
.1.3.6.1.2.1.153.2.1.2
spdIPEndpointAddress
.1.3.6.1.2.1.153.2.1.3
spdIPSourceType
.1.3.6.1.2.1.153.2.1.4
spdIPSourceAddress
.1.3.6.1.2.1.153.2.1.5
spdIPDestinationType
.1.3.6.1.2.1.153.2.1.6
spdIPDestinationAddress
.1.3.6.1.2.1.153.2.1.7
spdPacketDirection
.1.3.6.1.2.1.153.2.1.8
spdPacketPart .1.3.6.1.2.1.153.2.1.9
spdConformanceObjects .1.3.6.1.2.1.153.3
spdCompliances .1.3.6.1.2.1.153.3.1
spdGroups .1.3.6.1.2.1.153.3.2
spdActions .1.3.6.1.2.1.153.4

Notifications/Traps

NameOIDDescription
spdActionNotification








.1.3.6.1.2.1.153.2.0.1
on that an action was executed by a rule.
Only actions with logging enabled will result in this
notification getting sent.  The object includes the
spdActionExecuted object, which will indicate which action
was executed within the scope of the rule.  Additionally,
the spdIPSourceType, spdIPSourceAddress,
spdIPDestinationType, and spdIPDestinationAddress objects
are included to indicate the packet source and destination
of the packet that triggered the action.  Finally, the
spdIPEndpointAddType, spdIPEndpointAddress, and
spdPacketDirection objects indicate which interface the
executed action was associated with, and if the packet was
ingress or egress through the endpoint.
          
A spdActionNotification SHOULD be limited to a maximum of
one notification sent per minute for any action
notifications that do not have any other configuration
controlling their send rate.
          
Note that compound actions with multiple executed
sub-actions may result in multiple notifications being sent
from a single rule execution.
spdPacketNotification









.1.3.6.1.2.1.153.2.0.2
on that a packet passed through a Security
Association (SA).  Only SAs created by actions with packet
logging enabled will result in this notification getting
sent.  The objects sent MUST include the spdActionExecuted,
which will indicate which action was executed within the
scope of the rule.  Additionally, the spdIPSourceType,
spdIPSourceAddress, spdIPDestinationType, and
spdIPDestinationAddress objects MUST be included to
indicate the packet source and destination of the packet
that triggered the action.  The spdIPEndpointAddType,
spdIPEndpointAddress, and spdPacketDirection objects are
included to indicate which endpoint the packet was
associated with.  Finally, spdPacketPart is included to
enable sending a variable sized part of the front of the
packet with the size dependent on the value of the object of
TC syntax 'SpdIPPacketLogging', which indicated that logging
should be done.
          
A spdPacketNotification SHOULD be limited to a maximum of
one notification sent per minute for any action
notifications that do not have any other configuration
controlling their send rate.
          
An action notification SHOULD be limited to a maximum of
one notification sent per minute for any action
notifications that do not have any other configuration
controlling their send rate.